SSO Directory
Table of Contents
Privileges
AddMemberToGroup
description: Adds member to the group in the directory that AWS SSO provides by default
access level: Permissions management
resource types
{
"": {
"resource_type": "",
"required": false,
"condition_keys": [],
"dependent_actions": []
}
}
CompleteVirtualMfaDeviceRegistration
description: Completes the creation process of a virtual MFA device
access level: Write
resource types
{
"": {
"resource_type": "",
"required": false,
"condition_keys": [],
"dependent_actions": []
}
}
CreateAlias
description: Creates an alias for the directory that AWS SSO provides by default
access level: Permissions management
resource types
{
"": {
"resource_type": "",
"required": false,
"condition_keys": [],
"dependent_actions": []
}
}
CreateBearerToken
description: Creates a bearer token for a given provisioning tenant.
access level: Write
resource types
{
"": {
"resource_type": "",
"required": false,
"condition_keys": [],
"dependent_actions": []
}
}
CreateExternalIdPConfigurationForDirectory
description: Create an External Identity Provider configuration for the directory
access level: Write
resource types
{
"": {
"resource_type": "",
"required": false,
"condition_keys": [],
"dependent_actions": []
}
}
CreateGroup
description: Creates a group in the directory that AWS SSO provides by default
access level: Permissions management
resource types
{
"": {
"resource_type": "",
"required": false,
"condition_keys": [],
"dependent_actions": []
}
}
CreateProvisioningTenant
description: Creates a provisioning tenant for a given directory.
access level: Write
resource types
{
"": {
"resource_type": "",
"required": false,
"condition_keys": [],
"dependent_actions": []
}
}
CreateUser
description: Creates a user in the directory that AWS SSO provides by default
access level: Permissions management
resource types
{
"": {
"resource_type": "",
"required": false,
"condition_keys": [],
"dependent_actions": []
}
}
DeleteBearerToken
description: Deletes the bearer token.
access level: Write
resource types
{
"": {
"resource_type": "",
"required": false,
"condition_keys": [],
"dependent_actions": []
}
}
DeleteExternalIdPConfigurationForDirectory
description: Delete an External Identity Provider configuration associated with the directory
access level: Write
resource types
{
"": {
"resource_type": "",
"required": false,
"condition_keys": [],
"dependent_actions": []
}
}
DeleteGroup
description: Deletes a group from the directory that AWS SSO provides by default
access level: Permissions management
resource types
{
"": {
"resource_type": "",
"required": false,
"condition_keys": [],
"dependent_actions": []
}
}
DeleteMfaDeviceForUser
description: Deletes a MFA device by device name for a given user
access level: Write
resource types
{
"": {
"resource_type": "",
"required": false,
"condition_keys": [],
"dependent_actions": []
}
}
DeleteProvisioningTenant
description: Deletes the provisioning tenant.
access level: Write
resource types
{
"": {
"resource_type": "",
"required": false,
"condition_keys": [],
"dependent_actions": []
}
}
DeleteUser
description: Deletes a user from the directory that AWS SSO provides by default
access level: Permissions management
resource types
{
"": {
"resource_type": "",
"required": false,
"condition_keys": [],
"dependent_actions": []
}
}
DescribeDirectory
description: Retrieve information about the directory that AWS SSO provides by default
access level: Read
resource types
{
"": {
"resource_type": "",
"required": false,
"condition_keys": [],
"dependent_actions": []
}
}
DescribeGroups
description: Retrieves information about group from the directory that AWS SSO provides by default
access level: List
resource types
{
"": {
"resource_type": "",
"required": false,
"condition_keys": [],
"dependent_actions": []
}
}
DescribeUsers
description: Retrieves information about user from the directory that AWS SSO provides by default
access level: List
resource types
{
"": {
"resource_type": "",
"required": false,
"condition_keys": [],
"dependent_actions": []
}
}
DisableExternalIdPConfigurationForDirectory
description: Disable authentication of end users with an External Identity Provider
access level: Write
resource types
{
"": {
"resource_type": "",
"required": false,
"condition_keys": [],
"dependent_actions": []
}
}
DisableUser
description: Deactivates user in the directory that AWS SSO provides by default
access level: Permissions management
resource types
{
"": {
"resource_type": "",
"required": false,
"condition_keys": [],
"dependent_actions": []
}
}
EnableExternalIdPConfigurationForDirectory
description: Enable authentication of end users with an External Identity Provider
access level: Write
resource types
{
"": {
"resource_type": "",
"required": false,
"condition_keys": [],
"dependent_actions": []
}
}
EnableUser
description: Activates user in the directory that AWS SSO provides by default
access level: Permissions management
resource types
{
"": {
"resource_type": "",
"required": false,
"condition_keys": [],
"dependent_actions": []
}
}
GetAWSSPConfigurationForDirectory
description: Retrieve the AWS SSO Service Provider configurations for the directory
access level: Read
resource types
{
"": {
"resource_type": "",
"required": false,
"condition_keys": [],
"dependent_actions": []
}
}
ListBearerTokens
description: Lists bearer tokens for a given provisioning tenant.
access level: List
resource types
{
"": {
"resource_type": "",
"required": false,
"condition_keys": [],
"dependent_actions": []
}
}
ListExternalIdPConfigurationsForDirectory
description: List all the External Identity Provider configurations created for the directory
access level: List
resource types
{
"": {
"resource_type": "",
"required": false,
"condition_keys": [],
"dependent_actions": []
}
}
ListGroupsForUser
description: Lists groups for a user from the directory that AWS SSO provides by default
access level: List
resource types
{
"": {
"resource_type": "",
"required": false,
"condition_keys": [],
"dependent_actions": []
}
}
ListMembersInGroup
description: Retrieves all members that are part of the group in the directory that AWS SSO provides by default
access level: List
resource types
{
"": {
"resource_type": "",
"required": false,
"condition_keys": [],
"dependent_actions": []
}
}
ListMfaDevicesForUser
description: Lists all active MFA devices and their MFA device metadata for a user
access level: List
resource types
{
"": {
"resource_type": "",
"required": false,
"condition_keys": [],
"dependent_actions": []
}
}
ListProvisioningTenants
description: Lists provisioning tenants for a given directory.
access level: List
resource types
{
"": {
"resource_type": "",
"required": false,
"condition_keys": [],
"dependent_actions": []
}
}
RemoveMemberFromGroup
description: Removes member that are part of the group in the directory that AWS SSO provides by default
access level: Permissions management
resource types
{
"": {
"resource_type": "",
"required": false,
"condition_keys": [],
"dependent_actions": []
}
}
SearchGroups
description: Search for groups within the associated directory
access level: Read
resource types
{
"": {
"resource_type": "",
"required": false,
"condition_keys": [],
"dependent_actions": []
}
}
SearchUsers
description: Search for users within the associated directory
access level: Read
resource types
{
"": {
"resource_type": "",
"required": false,
"condition_keys": [],
"dependent_actions": []
}
}
StartVirtualMfaDeviceRegistration
description: Begins the creation process of virtual mfa device
access level: Write
resource types
{
"": {
"resource_type": "",
"required": false,
"condition_keys": [],
"dependent_actions": []
}
}
UpdateExternalIdPConfigurationForDirectory
description: Update an External Identity Provider configuration associated with the directory
access level: Write
resource types
{
"": {
"resource_type": "",
"required": false,
"condition_keys": [],
"dependent_actions": []
}
}
UpdateGroup
description: Updates information about group in the directory that AWS SSO provides by default
access level: Permissions management
resource types
{
"": {
"resource_type": "",
"required": false,
"condition_keys": [],
"dependent_actions": []
}
}
UpdatePassword
description: Updates password by sending password reset link via email or generating one time password for a user in the directory that AWS SSO provides by default
access level: Permissions management
resource types
{
"": {
"resource_type": "",
"required": false,
"condition_keys": [],
"dependent_actions": []
}
}
UpdateUser
description: Updates user information in the directory that AWS SSO provides by default
access level: Permissions management
resource types
{
"": {
"resource_type": "",
"required": false,
"condition_keys": [],
"dependent_actions": []
}
}
VerifyEmail
description: Verify email address of an User
access level: Permissions management
resource types
{
"": {
"resource_type": "",
"required": false,
"condition_keys": [],
"dependent_actions": []
}
}